www.broadbandreports.com
  republican-creole
Search:  

 
   AllHot TopicsCable SupportTelco SupportHardware etcSecurityClubsGallery»»






how-to block ads


 
Forums » Up and Running » Security » Security » Microsoft Security Advisory (950627)
 
Search Topic:
  Social:
topic feed
 
Posting
toggle:
flat / full
normal / watch
Post a:
Post a:
Security Software Updates - 21 Mar 2008 »
« [nebuad] trying to understand the "technology"  
AuthorAll Replies


NICK ADSL UK
Premium,MVM
join:2004-02-22

Microsoft Security Advisory (950627)

MSRC Blog: Microsoft Security Advisory (950627)
quote:
Hello, Bill here,


I wanted to let you know that we have just posted Microsoft Security Advisory (950627).

»www.microsoft.com/technet/securi···627.mspx

This advisory contains information about a very limited, targeted attack exploiting a vulnerability in Microsoft Jet Database Engine. Our initial investigation has shown that this vulnerability affects customers using Microsoft Word 2000 Service Pack 3, Microsoft Word 2002 Service Pack 3, Microsoft Word 2003 Service Pack 2, Microsoft Word 2003 Service Pack 3, Microsoft Word 2007 and Microsoft Word 2007 Service Pack 1 on Microsoft Windows 2000, Windows XP, or Windows Server 2003 Service Pack 1.

Customers running Windows Server 2003 Service Pack 2, Windows Vista, and Windows Vista Service Pack 1 are not vulnerable to the buffer overrun being attacked, as they include a version of the Microsoft Jet Database Engine that is not vulnerable to this issue.

We’ve activated our Software Security Incident Response Process (SSIRP) to investigate the vulnerability and have identified steps customers can take to protect themselves in the workaround section. As part of our SSIRP process, we currently have teams working to develop an update of appropriate quality for release in our regularly scheduled bulletin process or as an out-of-band update, depending on customer impact. In the meantime, we encourage customers to review the advisory and implement the workarounds.

While the attack appears to be targeted, and not widespread, we are monitoring the issue and are working with our MSRA partners to help protect customers. We will update the Advisory and this blog as new information becomes available.

Bill Sisk

*This posting is provided "AS IS" with no warranties, and confers no rights.*
--
Wilders Security Forum Admin
Microsoft MVP - Consumer Security

Forums » Up and Running » Security » SecuritySecurity Software Updates - 21 Mar 2008 »
« [nebuad] trying to understand the "technology"  

Most commented news this week
· [81] New Broadband Data Shows U.S. To Be Thoroughly Mediocre
· [64] Sprint To Impose 5GB Monthly EVDO Cap
· [37] Sandvine Jumps On 'Protocol Agnostic' Bandwagon
· [37] Comcast Installs DOCSIS 3.0 In Two New Markets
· [36] Sprint Broadband Direct Goes Offline July 31
· [36] Netflix Offers Broadband Set-Top Box
· [27] Dual HD Stream U-Verse Expanding
· [27] NYC FiOS Public Hearing Today
· [24] Congressmen Want To Chat With Charter Over Privacy
· [24] Bell Canada Must Prove Congestion Claims
Tuesday, 20-May
15:28:40
Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
8th year online! © 1999-2008 dslreports.com.
page compression OFF